mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
docs: add more specific steps and information about oidc refresh tokens (#18336)
closes https://github.com/coder/coder/issues/18307 relates to https://github.com/coder/coder/pull/18318 preview: - [refresh-tokens](https://coder.com/docs/@18307-refresh-tokens/admin/users/oidc-auth/refresh-tokens) - [configuring-okta](https://coder.com/docs/@18307-refresh-tokens/tutorials/configuring-okta) ~(not sure why @Emyrk 's photo is so huge there though)~ ✔️ - [x] removed from [idp-sync](https://coder.com/docs/@18307-refresh-tokens/admin/users/idp-sync) to do: - move keycloak - add ping federate and azure - edit text (possibly placeholders for now - I want to see how it all relates and edit it again. right now, there's a note about the same thing in every section in way that's not super helpful/necessary) - ~convert some paragraphs to OL~ calling this out of scope for now --------- Co-authored-by: EdwardAngert <17991901+EdwardAngert@users.noreply.github.com>
This commit is contained in:
co-authored by
EdwardAngert
parent
095007766b
commit
5c16079aff
@@ -304,7 +304,7 @@ Visit the Coder UI to confirm these changes:
|
||||
|
||||
```env
|
||||
# Depending on your identity provider configuration, you may need to explicitly request a "roles" scope
|
||||
CODER_OIDC_SCOPES=openid,profile,email,roles
|
||||
CODER_OIDC_SCOPES=openid,profile,email,offline_access,roles
|
||||
|
||||
# The following fields are required for role sync:
|
||||
CODER_OIDC_USER_ROLE_FIELD=roles
|
||||
@@ -517,7 +517,7 @@ Steps to troubleshoot.
|
||||
|
||||
## Provider-Specific Guides
|
||||
|
||||
Below are some details specific to individual OIDC providers.
|
||||
<div class="tabs">
|
||||
|
||||
### Active Directory Federation Services (ADFS)
|
||||
|
||||
@@ -577,33 +577,8 @@ Below are some details specific to individual OIDC providers.
|
||||
groups claim field.
|
||||
Use [this answer from Stack Overflow](https://stackoverflow.com/a/55570286) for an example.
|
||||
|
||||
### Keycloak
|
||||
## Next Steps
|
||||
|
||||
The `access_type` parameter has two possible values: `online` and `offline`.
|
||||
By default, the value is set to `offline`.
|
||||
|
||||
This means that when a user authenticates using OIDC, the application requests
|
||||
offline access to the user's resources, including the ability to refresh access
|
||||
tokens without requiring the user to reauthenticate.
|
||||
|
||||
To enable the `offline_access` scope which allows for the refresh token
|
||||
functionality, you need to add it to the list of requested scopes during the
|
||||
authentication flow.
|
||||
Including the `offline_access` scope in the requested scopes ensures that the
|
||||
user is granted the necessary permissions to obtain refresh tokens.
|
||||
|
||||
By combining the `{"access_type":"offline"}` parameter in the OIDC Auth URL with
|
||||
the `offline_access` scope, you can achieve the desired behavior of obtaining
|
||||
refresh tokens for offline access to the user's resources.
|
||||
|
||||
### Google
|
||||
|
||||
To ensure Coder receives a refresh token when users authenticate with Google
|
||||
directly, set the `prompt` to `consent` in the auth URL parameters. Without
|
||||
this, users will be logged out after 1 hour.
|
||||
|
||||
In your Coder configuration:
|
||||
|
||||
```shell
|
||||
CODER_OIDC_AUTH_URL_PARAMS='{"access_type": "offline", "prompt": "consent"}'
|
||||
```
|
||||
- [Configure OIDC Refresh Tokens](./oidc-auth/refresh-tokens.md)
|
||||
- [Organizations](./organizations.md)
|
||||
- [Groups & Roles](./groups-roles.md)
|
||||
|
||||
Reference in New Issue
Block a user